
# Security update for the Linux Kernel Announcement ID: SUSE-SU-2025:0203-1 Release Date: 2025-01-21T13:58:43Z Rating: important References: * bsc#1170891 * bsc#1173139 * bsc#1185010 * bsc#1190358 * bsc#1190428 * bsc#1209798 * bsc#1215304 * bsc#1222878 * bsc#1228466 * bsc#1230697 * bsc#1232436 * bsc#1233070 * bsc#1233642 * bsc#1234281 * bsc#1234282 * bsc#1234846 * bsc#1234853 * bsc#1234891 * bsc#1234921 * bsc#1234960 * bsc#1234963 * bsc#1235004 * bsc#1235035 * bsc#1235054 * bsc#1235056 * bsc#1235061 * bsc#1235073 * bsc#1235220 * bsc#1235224 * bsc#1235246 * bsc#1235507 Cross-References: * CVE-2021-47202 * CVE-2022-49035 * CVE-2024-41087 * CVE-2024-50154 * CVE-2024-53095 * CVE-2024-53142 * CVE-2024-53146 * CVE-2024-53156 * CVE-2024-53173 * CVE-2024-53179 * CVE-2024-53206 * CVE-2024-53214 * CVE-2024-53239 * CVE-2024-53240 * CVE-2024-53241 * CVE-2024-56539 * CVE-2024-56548 * CVE-2024-56570 * CVE-2024-56598 * CVE-2024-56604 * CVE-2024-56605 * CVE-2024-56619 * CVE-2024-8805 CVSS scores: * CVE-2021-47202 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-47202 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-49035 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-49035 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-41087 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41087 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50154 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53095 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53095 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2024-53142 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53146 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53146 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53156 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53156 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53179 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53179 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53206 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2024-53206 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2024-53206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53214 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53214 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53239 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53239 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53241 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-53241 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-56539 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56539 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-56548 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56548 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56570 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56570 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56598 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56598 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56598 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56604 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56604 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56604 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56605 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56605 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56619 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56619 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 23 vulnerabilities and has eight security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2024-41087: Fix double free on error (bsc#1228466). * CVE-2024-53095: smb: client: Fix use-after-free of network namespace (bsc#1233642). * CVE-2024-53146: NFSD: Prevent a potential integer overflow (bsc#1234853). * CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() (bsc#1234846). * CVE-2024-53173: NFSv4.0: Fix a use-after-free problem in the asynchronous open() (bsc#1234891). * CVE-2024-53179: smb: client: fix use-after-free of signing key (bsc#1234921). * CVE-2024-53214: vfio/pci: Properly hide first-in-list PCIe extended capability (bsc#1235004). * CVE-2024-53239: ALSA: 6fire: Release resources at card release (bsc#1235054). * CVE-2024-53240: xen/netfront: fix crash when removing device (bsc#1234281). * CVE-2024-53241: x86/xen: use new hypercall functions instead of hypercall page (XSA-466 bsc#1234282). * CVE-2024-56539: wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan() (bsc#1234963). * CVE-2024-56548: hfsplus: do not query the device logical block size multiple times (bsc#1235073). * CVE-2024-56570: ovl: Filter invalid inodes with missing lookup function (bsc#1235035). * CVE-2024-56598: jfs: array-index-out-of-bounds fix in dtReadFirst (bsc#1235220). * CVE-2024-56604: Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() (bsc#1235056). * CVE-2024-56605: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (bsc#1235061). * CVE-2024-56619: nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry() (bsc#1235224). * CVE-2024-8805: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE (bsc#1230697). The following non-security bugs were fixed: * Drop a couple of block layer git-fixes (bsc#1170891 bsc#1173139) * KVM: x86: fix sending PV IPI (git-fixes). * fixup "rpm: support gz and zst compression methods" once more (bsc#1190428, bsc#1190358) * idpf: add support for SW triggered interrupts (bsc#1235507). * idpf: enable WB_ON_ITR (bsc#1235507). * idpf: trigger SW interrupt when exiting wb_on_itr mode (bsc#1235507). * kernel-binary: do not BuildIgnore m4. It is actually needed for regenerating zconf when it is not up-to-date due to merge. * net: mana: Increase the DEF_RX_BUFFERS_PER_QUEUE to 1024 (bsc#1235246). * rpm/kernel-binary.spec.in: Fix build regression The previous fix forgot to take over grep -c option that broke the conditional expression * scsi: storvsc: Do not flag MAINTENANCE_IN return of SRB_STATUS_DATA_OVERRUN as an error (git-fixes). * smb: client: fix TCP timers deadlock after rmmod (git-fixes) [hcarvalho: this fixes issue discussed in bsc#1233642]. * supported.conf: add bsc1185010 dependency * supported.conf: hyperv_drm (jsc#sle-19733) * usb: roles: Call try_module_get() from usb_role_switch_find_by_fwnode() (git-fixes). * usb: typec: tps6598x: Fix return value check in tps6598x_probe() (git- fixes). * x86/bug: Merge annotate_reachable() into _BUG_FLAGS() asm (git-fixes). * x86/fpu/xsave: Handle compacted offsets correctly with supervisor states (git-fixes). * x86/fpu/xstate: Fix the ARCH_REQ_XCOMP_PERM implementation (git-fixes). * x86/fpu: Remove unused supervisor only offsets (git-fixes). * x86/kvm: Do not use pv tlb/ipi/sched_yield if on 1 vCPU (git-fixes). * x86/mce/inject: Avoid out-of-bounds write when setting flags (git-fixes). * x86/mce: Allow instrumentation during task work queueing (git-fixes). * x86/mce: Mark mce_end() noinstr (git-fixes). * x86/mce: Mark mce_panic() noinstr (git-fixes). * x86/mce: Mark mce_read_aux() noinstr (git-fixes). * x86/mm: Flush global TLB when switching to trampoline page-table (git- fixes). * x86/sgx: Free backing memory after faulting the enclave page (git-fixes). * x86/sgx: Silence softlockup detection when releasing large enclaves (git- fixes). * x86/uaccess: Move variable into switch case statement (git-fixes). * x86: Annotate call_on_stack() (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-203=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-203=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-203=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-203=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-203=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-203=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2025-203=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-203=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-203=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-203=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-203=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-203=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-203=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-203=1 ## Package List: * openSUSE Leap 15.4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * kernel-source-vanilla-5.14.21-150400.24.147.1 * kernel-docs-html-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (nosrc ppc64le x86_64) * kernel-debug-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (ppc64le x86_64) * kernel-debug-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-debug-debugsource-5.14.21-150400.24.147.1 * kernel-debug-debuginfo-5.14.21-150400.24.147.1 * kernel-debug-devel-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-5.14.21-150400.24.147.1 * kernel-kvmsmall-debuginfo-5.14.21-150400.24.147.1 * kernel-kvmsmall-debugsource-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-base-rebuild-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * kernel-syms-5.14.21-150400.24.147.1 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-obs-build-debugsource-5.14.21-150400.24.147.1 * reiserfs-kmp-default-5.14.21-150400.24.147.1 * kselftests-kmp-default-debuginfo-5.14.21-150400.24.147.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-obs-qa-5.14.21-150400.24.147.1 * kernel-default-optional-debuginfo-5.14.21-150400.24.147.1 * kernel-default-optional-5.14.21-150400.24.147.1 * kernel-default-livepatch-5.14.21-150400.24.147.1 * dlm-kmp-default-5.14.21-150400.24.147.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.147.1 * cluster-md-kmp-default-5.14.21-150400.24.147.1 * ocfs2-kmp-default-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kselftests-kmp-default-5.14.21-150400.24.147.1 * kernel-default-extra-debuginfo-5.14.21-150400.24.147.1 * kernel-default-extra-5.14.21-150400.24.147.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-obs-build-5.14.21-150400.24.147.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.147.1 * gfs2-kmp-default-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_147-default-1-150400.9.3.1 * kernel-livepatch-5_14_21-150400_24_147-default-debuginfo-1-150400.9.3.1 * kernel-livepatch-SLE15-SP4_Update_35-debugsource-1-150400.9.3.1 * kernel-default-livepatch-devel-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150400.24.147.1 * kernel-zfcpdump-debuginfo-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (nosrc) * dtb-aarch64-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64) * cluster-md-kmp-64kb-5.14.21-150400.24.147.1 * gfs2-kmp-64kb-5.14.21-150400.24.147.1 * dtb-allwinner-5.14.21-150400.24.147.1 * gfs2-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * reiserfs-kmp-64kb-5.14.21-150400.24.147.1 * kernel-64kb-extra-debuginfo-5.14.21-150400.24.147.1 * dtb-freescale-5.14.21-150400.24.147.1 * dtb-amd-5.14.21-150400.24.147.1 * dtb-amlogic-5.14.21-150400.24.147.1 * reiserfs-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * dlm-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * kselftests-kmp-64kb-5.14.21-150400.24.147.1 * dtb-apm-5.14.21-150400.24.147.1 * kernel-64kb-extra-5.14.21-150400.24.147.1 * dtb-qcom-5.14.21-150400.24.147.1 * dtb-arm-5.14.21-150400.24.147.1 * dlm-kmp-64kb-5.14.21-150400.24.147.1 * dtb-lg-5.14.21-150400.24.147.1 * kernel-64kb-optional-debuginfo-5.14.21-150400.24.147.1 * ocfs2-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * cluster-md-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * dtb-cavium-5.14.21-150400.24.147.1 * dtb-apple-5.14.21-150400.24.147.1 * dtb-mediatek-5.14.21-150400.24.147.1 * ocfs2-kmp-64kb-5.14.21-150400.24.147.1 * dtb-broadcom-5.14.21-150400.24.147.1 * dtb-exynos-5.14.21-150400.24.147.1 * dtb-xilinx-5.14.21-150400.24.147.1 * dtb-marvell-5.14.21-150400.24.147.1 * kernel-64kb-debugsource-5.14.21-150400.24.147.1 * kselftests-kmp-64kb-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-5.14.21-150400.24.147.1 * dtb-nvidia-5.14.21-150400.24.147.1 * dtb-rockchip-5.14.21-150400.24.147.1 * kernel-64kb-optional-5.14.21-150400.24.147.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.147.1 * dtb-sprd-5.14.21-150400.24.147.1 * kernel-64kb-debuginfo-5.14.21-150400.24.147.1 * dtb-renesas-5.14.21-150400.24.147.1 * dtb-hisilicon-5.14.21-150400.24.147.1 * dtb-altera-5.14.21-150400.24.147.1 * dtb-socionext-5.14.21-150400.24.147.1 * dtb-amazon-5.14.21-150400.24.147.1 * openSUSE Leap 15.4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Live Patching 15-SP4 (nosrc) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_147-default-debuginfo-1-150400.9.3.1 * kernel-default-livepatch-devel-5.14.21-150400.24.147.1 * kernel-livepatch-5_14_21-150400_24_147-default-1-150400.9.3.1 * kernel-livepatch-SLE15-SP4_Update_35-debugsource-1-150400.9.3.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * kernel-default-livepatch-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-debuginfo-5.14.21-150400.24.147.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.147.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.147.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.147.1 * cluster-md-kmp-default-5.14.21-150400.24.147.1 * ocfs2-kmp-default-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * gfs2-kmp-default-5.14.21-150400.24.147.1 * dlm-kmp-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (nosrc) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * kernel-64kb-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-5.14.21-150400.24.147.1 * kernel-64kb-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-obs-build-debugsource-5.14.21-150400.24.147.1 * reiserfs-kmp-default-5.14.21-150400.24.147.1 * kernel-obs-build-5.14.21-150400.24.147.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * kernel-64kb-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-5.14.21-150400.24.147.1 * kernel-64kb-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-obs-build-debugsource-5.14.21-150400.24.147.1 * reiserfs-kmp-default-5.14.21-150400.24.147.1 * kernel-obs-build-5.14.21-150400.24.147.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64) * kernel-64kb-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-64kb-devel-5.14.21-150400.24.147.1 * kernel-64kb-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-obs-build-debugsource-5.14.21-150400.24.147.1 * reiserfs-kmp-default-5.14.21-150400.24.147.1 * kernel-obs-build-5.14.21-150400.24.147.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch nosrc) * kernel-docs-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (s390x) * kernel-zfcpdump-debugsource-5.14.21-150400.24.147.1 * kernel-zfcpdump-debuginfo-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-obs-build-debugsource-5.14.21-150400.24.147.1 * reiserfs-kmp-default-5.14.21-150400.24.147.1 * kernel-obs-build-5.14.21-150400.24.147.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.147.1 * SUSE Manager Proxy 4.3 (nosrc x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Manager Proxy 4.3 (x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Manager Proxy 4.3 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Manager Retail Branch Server 4.3 (nosrc x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Manager Server 4.3 (nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.147.1 * SUSE Manager Server 4.3 (ppc64le x86_64) * kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.147.1 * kernel-syms-5.14.21-150400.24.147.1 * kernel-default-debuginfo-5.14.21-150400.24.147.1 * kernel-default-devel-5.14.21-150400.24.147.1 * kernel-default-debugsource-5.14.21-150400.24.147.1 * SUSE Manager Server 4.3 (noarch) * kernel-source-5.14.21-150400.24.147.1 * kernel-macros-5.14.21-150400.24.147.1 * kernel-devel-5.14.21-150400.24.147.1 * SUSE Manager Server 4.3 (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.147.1 * SUSE Manager Server 4.3 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150400.24.147.1 * kernel-zfcpdump-debuginfo-5.14.21-150400.24.147.1 ## References: * https://www.suse.com/security/cve/CVE-2021-47202.html * https://www.suse.com/security/cve/CVE-2022-49035.html * https://www.suse.com/security/cve/CVE-2024-41087.html * https://www.suse.com/security/cve/CVE-2024-50154.html * https://www.suse.com/security/cve/CVE-2024-53095.html * https://www.suse.com/security/cve/CVE-2024-53142.html * https://www.suse.com/security/cve/CVE-2024-53146.html * https://www.suse.com/security/cve/CVE-2024-53156.html * https://www.suse.com/security/cve/CVE-2024-53173.html * https://www.suse.com/security/cve/CVE-2024-53179.html * https://www.suse.com/security/cve/CVE-2024-53206.html * https://www.suse.com/security/cve/CVE-2024-53214.html * https://www.suse.com/security/cve/CVE-2024-53239.html * https://www.suse.com/security/cve/CVE-2024-53240.html * https://www.suse.com/security/cve/CVE-2024-53241.html * https://www.suse.com/security/cve/CVE-2024-56539.html * https://www.suse.com/security/cve/CVE-2024-56548.html * https://www.suse.com/security/cve/CVE-2024-56570.html * https://www.suse.com/security/cve/CVE-2024-56598.html * https://www.suse.com/security/cve/CVE-2024-56604.html * https://www.suse.com/security/cve/CVE-2024-56605.html * https://www.suse.com/security/cve/CVE-2024-56619.html * https://www.suse.com/security/cve/CVE-2024-8805.html * https://bugzilla.suse.com/show_bug.cgi?id=1170891 * https://bugzilla.suse.com/show_bug.cgi?id=1173139 * https://bugzilla.suse.com/show_bug.cgi?id=1185010 * https://bugzilla.suse.com/show_bug.cgi?id=1190358 * https://bugzilla.suse.com/show_bug.cgi?id=1190428 * https://bugzilla.suse.com/show_bug.cgi?id=1209798 * https://bugzilla.suse.com/show_bug.cgi?id=1215304 * https://bugzilla.suse.com/show_bug.cgi?id=1222878 * https://bugzilla.suse.com/show_bug.cgi?id=1228466 * https://bugzilla.suse.com/show_bug.cgi?id=1230697 * https://bugzilla.suse.com/show_bug.cgi?id=1232436 * https://bugzilla.suse.com/show_bug.cgi?id=1233070 * https://bugzilla.suse.com/show_bug.cgi?id=1233642 * https://bugzilla.suse.com/show_bug.cgi?id=1234281 * https://bugzilla.suse.com/show_bug.cgi?id=1234282 * https://bugzilla.suse.com/show_bug.cgi?id=1234846 * https://bugzilla.suse.com/show_bug.cgi?id=1234853 * https://bugzilla.suse.com/show_bug.cgi?id=1234891 * https://bugzilla.suse.com/show_bug.cgi?id=1234921 * https://bugzilla.suse.com/show_bug.cgi?id=1234960 * https://bugzilla.suse.com/show_bug.cgi?id=1234963 * https://bugzilla.suse.com/show_bug.cgi?id=1235004 * https://bugzilla.suse.com/show_bug.cgi?id=1235035 * https://bugzilla.suse.com/show_bug.cgi?id=1235054 * https://bugzilla.suse.com/show_bug.cgi?id=1235056 * https://bugzilla.suse.com/show_bug.cgi?id=1235061 * https://bugzilla.suse.com/show_bug.cgi?id=1235073 * https://bugzilla.suse.com/show_bug.cgi?id=1235220 * https://bugzilla.suse.com/show_bug.cgi?id=1235224 * https://bugzilla.suse.com/show_bug.cgi?id=1235246 * https://bugzilla.suse.com/show_bug.cgi?id=1235507